Impact
Oracle Reports Developer 14.1.2.0.0 suffers from a critical authentication bypass flaw that allows an attacker with network connectivity to the CORBA interface to execute arbitrary code and fully control the system. The vulnerability is rated CVSS 3.1 base score 9.8, indicating high confidentiality, integrity, and availability impact. Exploiting the flaw enables an attacker to take over the entire Oracle Reports Developer instance without needing valid credentials.
Affected Systems
The flaw affects Oracle Corporation's Oracle Reports Developer component of Oracle Fusion Middleware, specifically version 14.1.2.0.0. Any deployment exposed to the CORBA network channel is susceptible; no further version clarification is available in the data.
Risk and Exploitability
The vulnerability has a very high potential for exploitation due to its requirement of only network access and no authentication. The EPSS score is not available, but the lack of a KEV listing does not diminish the inherent risk. The likely attack vector is an unauthenticated remote attacker sending malicious CORBA requests, potentially leading to system compromise or conversion of the Reports Developer environment into a platform for further attacks.
OpenCVE Enrichment